CVE-2021-27051 is a Remote Code Execution vulnerability affecting Microsoft High Efficiency Video Coding (HEVC) extensions. With a CVSS score of 7.8 (High), it can be exploited locally with low attack complexity, requiring user interaction, to achieve high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it received limited community discussion and media coverage, primarily noted in Microsoft's March 2021 Patch Tuesday. Its EPSS score suggests a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:high_efficiency_video_coding:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.